Hive, also known as Hive ransomware, was a financially motivated ransomware-as-a-service operation active from June 2021 until its infrastructure was seized by the FBI and Europol in January 2023, ending the operation. Its developers maintained the ransomware and supporting infrastructure, while affiliates compromised victim networks and deployed the malware. By November 2022, Hive had victimized more than 1,300 companies worldwide and received approximately US$100 million in ransom payments. Its targets included healthcare and public health organizations, government facilities, communications providers, manufacturers, information technology companies, and legal services firms, with documented affiliate activity in the United States and Canada. Hive affiliates obtained initial access through exposed RDP and VPN services, compromised VPN credentials, phishing emails with malicious attachments, and exploitation of FortiOS and Microsoft Exchange vulnerabilities. Exploitation included CVE-2020-12812 to bypass FortiToken multifactor authentication and Exchange vulnerabilities associated with ProxyShell. Affiliates also abused legitimate remote monitoring and management tools, including SimpleHelp, for persistence and detection evasion. Hive ransomware supported Windows, Linux, VMware ESXi, and FreeBSD environments. Hive used double extortion, combining file encryption with threats to publish stolen information on its HiveLeaks leak site. Before encryption, its ransomware terminated backup and security processes, disabled antivirus protections, cleared Windows event logs, deleted volume shadow copies, and inhibited recovery. Operators negotiated payments through Tor-based live chat and sometimes contacted victims by telephone or email, demanding Bitcoin payments. Hive also reinfected organizations that restored their networks without paying. Its affiliate infrastructure supported rapid ransomware-build generation, victim tracking, and administrator-mediated negotiations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
Hive actors have also gained initial access to victim networks by exploiting Microsoft Exchange server vulnerabilities, including CVE-2021-31207.
Hive actors have also gained initial access to victim networks ... by exploiting the following vulnerabilities against Microsoft Exchange servers: ... CVE-2021-34473 ... - Microsoft Exchange Server Remote Code Execution Vulnerability.
Hive actors have also gained initial access to victim networks ... by exploiting the following vulnerabilities against Microsoft Exchange servers: ... CVE-2021-34523 ... - Microsoft Exchange Server Privilege Escalation Vulnerability.
Hive actors have bypassed multifactor authentication (MFA) and gained access to FortiOS servers by exploiting CVE-2020-12812.
Hive actors gain access to victim network by exploiting the following Microsoft Exchange vulnerabilities: CVE-2021-34473, CVE-2021-34523, CVE-2021-31207, CVE-2021-42321.
156 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Defunct ransomware group discussed as having TTP similarities to Play and as the suspected predecessor of Hunters International.
Mentioned as a competing ransomware group that relied on access brokers.
Named as one of multiple ransomware groups operating data leak sites and listing fresh victims.
Mentioned only as another ransomware operator using Rust.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.